IT Security Assessment of E-Commerce Platforms: P2C, Members Area, Passwordless Login, and Shipping with Multi-Carrier Integration
The assessment covered a P2C platform for maintaining product data across multiple shops, an online store with a members area and passwordless login, and a shipping solution managing multiple carriers with automated label generation. An image designer used to generate product visuals was also included.
We analyzed payment flows, session management, IDOR/access control, cross-site protections (CSRF/XSS), webhook and API security, upload/download paths, and secure implementation of passwordless methods (e.g., magic links/WebAuthn). We also reviewed tenant separation, rate limiting, input validation, and the protection of external storage/object stores to prevent data leakage and manipulation.
Talk now
to our
Pentest experts.
Contact us

OSCP, M.Sc. Security Management
Talk now to our Pentest experts.

OSCP, M.Sc. Security Management
Penetration Testing
Since 2013 we conduct professional penetration test, based on international industry standards and years of experience in penetration testing, red teaming and hacking.
As a company for professional penetration testing, we do some things differently than other pentest provider: As a penetration test firm, we do not sell vulnerability scans as pentest. We do also focus on business security risks. You are looking for a professionally conducted penetration tests? Get the binsec team for your Pentest. Read more about our pentest service.
Contact us